Hi:)<br><br>I used unbound-control-setup  to generate the keys; they are located in: /usr/local/etc/unbound/<br><br>using the tutorial from: <a href="http://www.howtoforge.com/installing-using-unbound-nameserver-on-debian-etch">http://www.howtoforge.com/installing-using-unbound-nameserver-on-debian-etch</a><br>
<br>i've noticed the installed unbound.conf file is in /usr/local/etc/unbound/unbound.conf ; which is used by the system<br><br>and in tutorial shpould be in /var/unbound/unbound.conf<br><br>at this momemnt I have no clue what's woring.. no info in logs..<br>
<br>Gabi<br><br><div class="gmail_quote">On Sun, May 17, 2009 at 10:34 PM, W.C.A. Wijngaards <span dir="ltr"><<a href="mailto:wouter@nlnetlabs.nl">wouter@nlnetlabs.nl</a>></span> wrote:<br><blockquote class="gmail_quote" style="border-left: 1px solid rgb(204, 204, 204); margin: 0pt 0pt 0pt 0.8ex; padding-left: 1ex;">
-----BEGIN PGP SIGNED MESSAGE-----<br>
Hash: SHA1<br>
<br>
Hi Gabriel,<br>
<br>
Did you run unbound-control-setup  to generate the key files?<br>
<br>
It seems like it cannot read<br>
/var/unbound/usr/local/etc/unbound/unbound_control.pem.  Could this be<br>
due to a chroot: "/var/unbound" setting; do you have that?  Can the<br>
unbound server read the keys?<br>
<br>
Where are the key files on your system?   What is the config file that<br>
unbound-control uses (unbound-control -h shows the name)?  Is that the<br>
correct config file?<br>
<br>
Best regards,<br>
   Wouter<br>
<div class="im"><br>
Gabriel Petrescu wrote:<br>
> about running unbound-control stat command<br>
><br>
> here I get several errors:<br>
><br>
> root@unbound3:~# unbound-control start<br>
> root@unbound3:~# unbound-control stats<br>
> error: Error setting up SSL_CTX client key and cert<br>
> 4281:error:02001002:system library:fopen:No such file or<br>
> directory:bss_file.c:352:fopen('/var/unbound/usr/local/etc/unbound/unbound_control.pem','r')<br>
> 4281:error:20074002:BIO routines:FILE_CTRL:system lib:bss_file.c:354:<br>
> 4281:error:140AD002:SSL routines:SSL_CTX_use_certificate_file:system<br>
> lib:ssl_rsa.c:470:<br>
><br>
<br>
</div>-----BEGIN PGP SIGNATURE-----<br>
Version: GnuPG v1.4.9 (GNU/Linux)<br>
Comment: Using GnuPG with Fedora - <a href="http://enigmail.mozdev.org" target="_blank">http://enigmail.mozdev.org</a><br>
<br>
iEYEARECAAYFAkoQZtMACgkQkDLqNwOhpPhWPwCfQwotVJE1tIJmt3PLGSpya90g<br>
j9EAoK4TWbe6n1bO50a4IjNXEx7jySa4<br>
=uylA<br>
-----END PGP SIGNATURE-----<br>
</blockquote></div><br>